CVE-2022-4364 is a critical command injection vulnerability affecting Teledyne FLIR AX8 devices running firmware versions up to 1.46.16. Specifically, an unauthenticated remote attacker can exploit a flaw in the palette.php component of the web service handler by manipulating the 'palette' argument. This allows for arbitrary command execution on the device, leading to complete compromise of confidentiality, integrity, and availability. While the vulnerability has been publicly disclosed, there is no evidence of active exploitation, nor are there readily available exploit modules in common frameworks like Metasploit or Nuclei, and community discussion is minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 1.46.0, < 1.46.16CPE matchmatch criteria | cpe:2.3:o:flir:flir_ax8_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.